-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 08 Aug 2023 04:35:25 +0200 Source: linux-signed-arm64 Architecture: source Version: 4.19.289+2 Distribution: buster-security Urgency: high Maintainer: Debian Kernel Team <debian-kernel@lists.debian.org> Changed-By: Ben Hutchings <benh@debian.org> Changes: linux-signed-arm64 (4.19.289+2) buster-security; urgency=high . * Sign kernel from linux 4.19.289-2 . * [x86] Add mitigations for Gather Data Sampling (GDS) (CVE-2022-40982) - init: Provide arch_cpu_finalize_init() - x86/cpu: Switch to arch_cpu_finalize_init() - ARM: cpu: Switch to arch_cpu_finalize_init() - init: Remove check_bugs() leftovers - init: Invoke arch_cpu_finalize_init() earlier - init, x86: Move mem_encrypt_init() into arch_cpu_finalize_init() - x86/fpu: Remove cpuinfo argument from init functions - x86/fpu: Mark init functions __init - x86/fpu: Move FPU initialization into arch_cpu_finalize_init() - x86/speculation: Add Gather Data Sampling mitigation - x86/speculation: Add force option to GDS mitigation - x86/speculation: Add Kconfig option for GDS - KVM: Add GDS_NO support to KVM - x86/xen: Fix secondary processors' FPU initialization - Documentation/x86: Fix backwards on/off logic about YMM support * [x86] cpu: Avoid ABI change for GDS mitigations Checksums-Sha1: e7a8b0eee098a0b74e22126c5ac262fa6b16821f 6605 linux-signed-arm64_4.19.289+2.dsc a20f38d6ce8dba314f33330c370ad9650ac46a82 2101632 linux-signed-arm64_4.19.289+2.tar.xz Checksums-Sha256: a64f351b947b362df7878961d4f3a85f3643cec22f1910d06544f50f7a8445cc 6605 linux-signed-arm64_4.19.289+2.dsc 51be404d1761d3e02b1116e4e1dc069eb5240ec69b564939a8aa94c47800aabd 2101632 linux-signed-arm64_4.19.289+2.tar.xz Files: e54e059dbe109ddfbde85ae55f95025c 6605 kernel optional linux-signed-arm64_4.19.289+2.dsc a0d0eb2ac8436d82efd4afecb49de495 2101632 kernel optional linux-signed-arm64_4.19.289+2.tar.xz -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEfKFfvHEI+gkU+E+di0FRiLdONzYFAmTT+AUACgkQi0FRiLdO NzYeNQ/6A37X/afvmuurPDqQM2v7RTA6sM2i8Tz8V0x8V6RtRrS62MLzmjzuW7mO ojK2P6ykPksTmEYo+gsTqInQVM27Q0aKHhZQoXLNpnWdk4ZWXjtfEGolbJiamzar pt7w7+/2YH3RAQuc4i+bTWkssVRvNB9mV6PeLmyfdoPKykOVMxisOhy7vsTnKl7w lqav/yOFCdVetdV8ikKKx8u5bH/3tHBkIgECnUGiCAJXjqFas039TbWEvw4B5rCa VttgAYlSbvcNc/RF5d/Gdrx+CPAUipv0NNQHhEB7Vq9hZnYHcCmLklKhlOVFhZ15 q3gk+aWs7ziKeHc2KJ4IFMd74FvjmKCLAupB6aHeeGm3PkY3FQy7bURQMXP9ayFk dJot5SiREbPxvkPIbQ58/y7EteNk1P94lWSy+wGA5kemacRJ2z5XXhhGO6TxFAC6 6zH5ld6qajcgmQD/gHXTTFypKPxOuc5fhEsI6ma5Uwzp04HzBpR37kebJWW5gt47 KUgtqHmuX6mudUbqlr4bX3GTdL1mJL1C//joBfuJw0QW7fUwv8MfPfxKdsiTa8io oRVpal2P2p2/DlimfCSCS16hOBU3J0kMFgQraqoIcRr4wkviHlb5COhP6DLkbCDn 4w3uf0jAN0gEeh27hcchW+bLBVKaFGOH3So7Xo5cuZH4L+Jn32Q= =jMY8 -----END PGP SIGNATURE-----